CVE-2026-92976: Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0
A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. An authenticated user could inject malicious HTML or JavaScript content into the fields containing their personal data. The content entered is stored and displayed without being properly sanitised when another user, including administrative staff, views the affected profile. Successful exploitation could allow JavaScript code to be executed in the victim’s browser, access to information available within the session, or the performance of actions using the victim’s permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
T-Systems TAO 2.0to a version that resolves this vulnerability.Fixed in 2602.0.0
Event History
Frequently Asked Questions
Who needs to be able to interact with the vulnerable functionality to exploit this issue?
An attacker needs an authenticated TAO 2.0 account and access to profile-management fields that accept personal-data content. They can store malicious HTML or JavaScript in those fields for execution when another user views the profile.
Which users are at risk when a malicious profile is viewed?
Any user who views the affected profile may execute the stored script in their browser, including administrative staff. The impact is bounded by information and actions available through that viewer's active session.
How can an organization determine whether it may have been exposed?
Review profile-management personal-data fields for unexpected HTML or JavaScript content, particularly in profiles created or edited by authenticated users. Also investigate administrative or user sessions that viewed profiles containing suspicious stored content.